-
Notifications
You must be signed in to change notification settings - Fork 512
Open
Description
would you like to restore
_WMI_LOGGER_CONTEXT::GetCpuClockinIfhReleaseas a complete release.
I haven't tried yet though, is there a need to scan stack by
INFINITYHOOK_MAGIC_1INFINITYHOOK_MAGIC_2every time enter syscall. AFAIK it hurts perfermance to some extent. or maybe when enterKiSystemCall64, address of [rsp+138h+Var_f8] is a fixed offset toPVOID* StackMax = (PVOID*)__readgsqword(OFFSET_KPCR_RSP_BASE).
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels